Understanding Azure Information Protection (AIP) Sensitivity Labels

When documents contain sensitive or confidential information, you may use AIP to protect the documents such that only authorized persons can open and read the documents. AIP is applicable to Office documents such as Microsoft Word, Excel, and PowerPoint.

Sensitivity Labels 

With Azure Information Protection (AIP), we apply a sensitivity label to classify a document according to the HKUST Data Classification Guidelines.  The sensitivity labels, “HKUST Restricted” and “Highly Confidential” will enforce encryption to protect documents such that they can only be accessed by authorized users [1].  Below is a summary of the sensitivity labels you may use to protect your documents with AIP. 

 

 

Sensitivity Labels 

HKUST Restricted 

Highly Confidential 

Public 

Suggested Usage 

A quick and simple way to protect a document for access by HKUST (CWB) staff only  

Protects documents for access by specific users who could be members of HKUST (CWB), HKUST (GZ) or external users.  

Optionally classify a document for public access.   

Authorized Users 

HKUST (CWB) staff members only 

Specified by the document owner [2] 

Documents do not have encryption protection and can be opened by anyone. 

Allowed Permissions 

Read and Write only 

Specified by the document owner 

No restrictions

 

Notes:

[1] Authorized users will need to login to Microsoft Office with their credentials.  For HKUST (CWB) staff, they need to login with their ITSO username (@ust.hk) and passwords.  Other users will need to login with their own accounts which have a valid Microsoft Office license.   

[2] You need to enter the username with which your authorized users will use to open the document.  The usernames will need to be valid Microsoft accounts which they use to activate their Microsoft Office.   For HKUST, you enter their email address, but alias (e.g. pchankl@ust.hk not peter.chan@ust.hk)  

Reference: